HIPAA Compliance for TB Control Programs: Handling Video Observed Therapy (VOT) Files

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance for TB Control Programs: Handling Video Observed Therapy (VOT) Files

Kevin Henry

HIPAA

August 22, 2026

6 minutes read
Share this article
HIPAA Compliance for TB Control Programs: Handling Video Observed Therapy (VOT) Files

Compliance Requirements for vDOT

Map HIPAA rules to vDOT workflows

Align each vDOT step—scheduling, recording, transmission, review, storage, and deletion—with the HIPAA Privacy, Security, and Breach Notification Rules. Identify where protected health information (PHI) is created, received, maintained, or transmitted, and document controls at every handoff.

Define roles, access, and the minimum necessary standard

Assign workforce roles for clinical review, technical administration, and compliance oversight. Limit access to the minimum necessary PHI for each role, and use role-based permissions to enforce it across applications, storage, and backups.

Conduct risk analysis and mitigation

Perform a formal risk analysis covering devices, networks, apps, and people. Address threats such as lost phones, misdirected files, or insecure home Wi‑Fi with safeguards like device encryption, strong authentication, and user training. Reassess risks whenever the workflow or vendor changes.

Business Associate Agreements (BAAs)

Execute BAAs with any vendor that stores, processes, or transmits VOT files. Verify security obligations, breach support, data return or deletion at contract end, and audit cooperation. Choose HIPAA-Compliant Software that is mature, well-supported, and transparent about its controls.

Protected Health Information Encryption

Require Protected Health Information Encryption in transit and at rest for all VOT artifacts, including cached mobile data, server databases, and backups. Manage encryption keys centrally, rotate them on a set schedule, and restrict key access to designated administrators only.

Patient Privacy and Security Measures

Access controls and authentication

Implement unique user IDs, multi-factor authentication for staff, automatic logoff, and session timeouts. Use audit logs to record access, changes, and exports of VOT files, and review those logs routinely.

Secure Video Transmission

Use Secure Video Transmission with modern protocols and certificate validation. Disable platform features that might route videos to personal cloud accounts, messaging apps, or device galleries. Block downloads unless clinically necessary and approved.

Device and environment safeguards

Enroll staff devices in mobile device management to enforce encryption, screen locks, and remote wipe. Provide patients with simple guidance: find a private space, avoid showing bystanders, and report lost or shared devices immediately.

Confidentiality Agreements

Have staff, contractors, and volunteers sign Confidentiality Agreements that address VOT-specific risks, personal device use, and social media prohibitions. Reinforce agreements through onboarding, annual training, and spot checks.

Informed Consent Documentation should explain the purpose of vDOT, how videos are recorded and transmitted, what PHI is captured, who can view it, retention and deletion timelines, potential risks, benefits, alternatives (including in-person DOT), and how to revoke consent without affecting standard care.

Process, readability, and retention

Provide consent materials in clear language and the patient’s preferred language. Capture signatures electronically or on paper, date them, and store consent alongside the patient record. Re-consent if the technology, vendor, or data use materially changes.

Special considerations

Address minors, guardianship, and patients with limited digital literacy. Offer accommodations such as live demonstrations, teach-back confirmation, and alternative DOT methods when vDOT is not feasible or acceptable.

Technology Assessment and Support

Selecting HIPAA-Compliant Software

Evaluate platforms for encryption, access controls, audit trails, secure messaging, content expiration, remote wipe, and API integrations. Confirm the vendor will sign a BAA, supports data export, and documents its security posture and uptime commitments.

Implementation and onboarding

Standardize configuration: disable camera-roll saves, enforce strong passcodes, and set automatic deletion after review. Pilot with a small cohort, validate throughput and video quality, then scale with documented procedures and checklists.

Ongoing support

Offer patient helpdesk hours, quick-start guides, and device loaners when possible. Train staff on troubleshooting connectivity, resubmission of failed uploads, and escalation paths for clinical or technical issues.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Data Storage and Backup Protocols

Retention and deletion

Define how long VOT files are retained, where they reside, and who can authorize exceptions. Prefer storing only clinically necessary clips and purge temporary caches automatically after successful review.

Data Backup Policies

Adopt Data Backup Policies that specify frequency, encryption, geographic redundancy, testing cadence, and recovery objectives. Ensure backups inherit access controls and are excluded from non-clinical analytics unless de-identified.

Encryption and key management

Encrypt servers and backups end-to-end. Separate encryption keys from data, restrict key custodians, and log all administrative actions related to key access, rotation, and recovery.

Program Monitoring and Evaluation

Operational performance indicators

  • Adherence: percent of scheduled doses verified via vDOT.
  • Timeliness: median time from patient upload to staff review.
  • Quality: rate of videos requiring resubmission due to technical issues.
  • Security: number of access exceptions, failed logins, or policy violations.

Quality assurance and Regulatory Compliance Audits

Run periodic Regulatory Compliance Audits to test user permissions, audit logs, consent records, and deletion events. Sample cases for minimum-necessary access and confirm BAAs, training, and incident drill documentation are current.

Incident response and continuous improvement

Maintain a documented incident response plan with clear triage, containment, notification, and post-incident review steps. Track corrective and preventive actions (CAPA) and fold lessons learned into revised policies and training.

Jurisdiction and disclosures

Account for state privacy laws, retention mandates, and public health reporting rules in addition to HIPAA. Limit disclosures to those permitted, document the basis for each disclosure, and maintain a clear accounting of disclosures upon request.

Breach handling and documentation

Define what constitutes a breach, how to investigate, and when to notify affected individuals and authorities. Keep comprehensive records of decisions, timelines, and remediation steps for legal defensibility.

Ethical practice

Protect dignity and reduce stigma by coaching on private recording settings and minimizing unnecessary identifiers in the frame. Provide equitable access through language support, device options, and alternatives to vDOT when needed.

Conclusion

To keep VOT effective and compliant, build privacy and security into every step: choose HIPAA-Compliant Software, obtain and store informed consent, encrypt data end-to-end, define retention and backups, monitor performance, and audit regularly. Clear roles, rigorous processes, and respectful patient engagement make vDOT safe, reliable, and patient-centered.

FAQs.

How does HIPAA apply to video observed therapy in TB control programs?

HIPAA governs how you create, transmit, store, access, and delete VOT files because they contain PHI. You must apply administrative, technical, and physical safeguards, limit access to the minimum necessary, maintain audit logs, and have BAAs with any vendor handling your VOT data.

What measures ensure the security of VOT files?

Use Protected Health Information Encryption at rest and in transit, Secure Video Transmission, multi-factor authentication, role-based access, device management with remote wipe, strict retention and deletion policies, and continuous log review with documented incident response.

Explain the purpose of vDOT, what will be recorded, how videos are transmitted and stored, who can see them, risks and benefits, alternatives to vDOT, retention and deletion timelines, and how to withdraw consent without disrupting access to standard care.

How can TB programs maintain compliance with HIPAA while using vDOT?

Adopt HIPAA-Compliant Software with a signed BAA, keep complete Informed Consent Documentation, implement Data Backup Policies, enforce access controls and encryption, train staff under Confidentiality Agreements, and perform regular Regulatory Compliance Audits to verify that policies match practice.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles